6.5

CVE-2025-20187

A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system.

This vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected system. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the affected system.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
CiscoCatalyst Sd-wan Manager Version17.2.4
CiscoCatalyst Sd-wan Manager Version17.2.5
CiscoCatalyst Sd-wan Manager Version17.2.6
CiscoCatalyst Sd-wan Manager Version17.2.7
CiscoCatalyst Sd-wan Manager Version17.2.8
CiscoCatalyst Sd-wan Manager Version17.2.9
CiscoCatalyst Sd-wan Manager Version17.2.10
CiscoCatalyst Sd-wan Manager Version18.2.0
CiscoCatalyst Sd-wan Manager Version18.3.0
CiscoCatalyst Sd-wan Manager Version18.3.1
CiscoCatalyst Sd-wan Manager Version18.3.1.1
CiscoCatalyst Sd-wan Manager Version18.3.3
CiscoCatalyst Sd-wan Manager Version18.3.3.1
CiscoCatalyst Sd-wan Manager Version18.3.4
CiscoCatalyst Sd-wan Manager Version18.3.5
CiscoCatalyst Sd-wan Manager Version18.3.6
CiscoCatalyst Sd-wan Manager Version18.3.6.1
CiscoCatalyst Sd-wan Manager Version18.3.7
CiscoCatalyst Sd-wan Manager Version18.3.8
CiscoCatalyst Sd-wan Manager Version18.4.0
CiscoCatalyst Sd-wan Manager Version18.4.0.1
CiscoCatalyst Sd-wan Manager Version18.4.1
CiscoCatalyst Sd-wan Manager Version18.4.3
CiscoCatalyst Sd-wan Manager Version18.4.4
CiscoCatalyst Sd-wan Manager Version18.4.5
CiscoCatalyst Sd-wan Manager Version18.4.6
CiscoCatalyst Sd-wan Manager Version18.4.302
CiscoCatalyst Sd-wan Manager Version18.4.303
CiscoCatalyst Sd-wan Manager Version18.4.501_es
CiscoCatalyst Sd-wan Manager Version19.0.0
CiscoCatalyst Sd-wan Manager Version19.0.1a
CiscoCatalyst Sd-wan Manager Version19.1.0
CiscoCatalyst Sd-wan Manager Version19.2.0
CiscoCatalyst Sd-wan Manager Version19.2.1
CiscoCatalyst Sd-wan Manager Version19.2.2
CiscoCatalyst Sd-wan Manager Version19.2.3
CiscoCatalyst Sd-wan Manager Version19.2.4
CiscoCatalyst Sd-wan Manager Version19.2.4.0.1
CiscoCatalyst Sd-wan Manager Version19.2.4.0.8
CiscoCatalyst Sd-wan Manager Version19.2.4.0.9
CiscoCatalyst Sd-wan Manager Version19.2.31
CiscoCatalyst Sd-wan Manager Version19.2.32
CiscoCatalyst Sd-wan Manager Version19.2.097
CiscoCatalyst Sd-wan Manager Version19.2.098
CiscoCatalyst Sd-wan Manager Version19.2.099
CiscoCatalyst Sd-wan Manager Version19.2.929
CiscoCatalyst Sd-wan Manager Version19.3.0
CiscoCatalyst Sd-wan Manager Version20.1.1
CiscoCatalyst Sd-wan Manager Version20.1.1.1
CiscoCatalyst Sd-wan Manager Version20.1.2
CiscoCatalyst Sd-wan Manager Version20.1.2_937
CiscoCatalyst Sd-wan Manager Version20.1.3
CiscoCatalyst Sd-wan Manager Version20.1.3.1
CiscoCatalyst Sd-wan Manager Version20.1.12
CiscoCatalyst Sd-wan Manager Version20.3.1
CiscoCatalyst Sd-wan Manager Version20.3.2
CiscoCatalyst Sd-wan Manager Version20.3.2.0.5
CiscoCatalyst Sd-wan Manager Version20.3.2.0.6
CiscoCatalyst Sd-wan Manager Version20.3.2.1
CiscoCatalyst Sd-wan Manager Version20.3.2.1_927
CiscoCatalyst Sd-wan Manager Version20.3.2.1_930
CiscoCatalyst Sd-wan Manager Version20.3.2_925
CiscoCatalyst Sd-wan Manager Version20.3.2_928
CiscoCatalyst Sd-wan Manager Version20.3.2_929
CiscoCatalyst Sd-wan Manager Version20.3.2_937
CiscoCatalyst Sd-wan Manager Version20.3.3
CiscoCatalyst Sd-wan Manager Version20.3.3.0.8
CiscoCatalyst Sd-wan Manager Version20.3.3.0.14
CiscoCatalyst Sd-wan Manager Version20.3.3.0.16
CiscoCatalyst Sd-wan Manager Version20.3.3.0.17
CiscoCatalyst Sd-wan Manager Version20.3.3.0.18
CiscoCatalyst Sd-wan Manager Version20.3.3.1
CiscoCatalyst Sd-wan Manager Version20.3.3.1.1
CiscoCatalyst Sd-wan Manager Version20.3.3.1.2
CiscoCatalyst Sd-wan Manager Version20.3.3.1.5
CiscoCatalyst Sd-wan Manager Version20.3.3.1.7
CiscoCatalyst Sd-wan Manager Version20.3.3.1.10
CiscoCatalyst Sd-wan Manager Version20.3.3.2
CiscoCatalyst Sd-wan Manager Version20.3.4
CiscoCatalyst Sd-wan Manager Version20.3.4.0.1
CiscoCatalyst Sd-wan Manager Version20.3.4.0.5
CiscoCatalyst Sd-wan Manager Version20.3.4.0.6
CiscoCatalyst Sd-wan Manager Version20.3.4.0.11
CiscoCatalyst Sd-wan Manager Version20.3.4.0.19
CiscoCatalyst Sd-wan Manager Version20.3.4.0.20
CiscoCatalyst Sd-wan Manager Version20.3.4.0.24
CiscoCatalyst Sd-wan Manager Version20.3.4.0.25
CiscoCatalyst Sd-wan Manager Version20.3.4.0.26
CiscoCatalyst Sd-wan Manager Version20.10.1
CiscoCatalyst Sd-wan Manager Version20.10.1.1
CiscoCatalyst Sd-wan Manager Version20.10.1.2
CiscoCatalyst Sd-wan Manager Version20.11.1
CiscoCatalyst Sd-wan Manager Version20.11.1.1
CiscoCatalyst Sd-wan Manager Version20.11.1.2
CiscoCatalyst Sd-wan Manager Version20.12.1
CiscoCatalyst Sd-wan Manager Version20.12.2
CiscoCatalyst Sd-wan Manager Version20.12.3
CiscoCatalyst Sd-wan Manager Version20.12.3.1
CiscoCatalyst Sd-wan Manager Version20.12.4
CiscoCatalyst Sd-wan Manager Version20.12.4.0.03
CiscoCatalyst Sd-wan Manager Version20.12.4.0.4
CiscoCatalyst Sd-wan Manager Version20.12.4.1
CiscoCatalyst Sd-wan Manager Version20.12.401
CiscoCatalyst Sd-wan Manager Version20.13.1
CiscoCatalyst Sd-wan Manager Version20.14.1
CiscoCatalyst Sd-wan Manager Version20.15.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.3% 0.534
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@cisco.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.